Catch 22 Solutions

Bespoke Cyber Solutions

Security research, bespoke software engineering, and secure development consulting.

What I Can Help With

I work where software, architecture, and security meet: assessing how systems fail, building practical mitigations, and creating tools when off-the-shelf answers are not enough.

01

Security Research & Assessment

Attacker-led assessment of applications, platforms, protocols, infrastructure, and product architectures. Useful when you need a deeper view than a checklist penetration test.

  • Vulnerability research and exploitability analysis
  • Reverse engineering of native code, protocols, and embedded systems
  • Windows, Linux, cloud, network, and distributed-system attack surfaces
02

Threat Modelling

Structured threat modelling for products, deployments, and delivery pipelines, with clear engineering actions rather than abstract risk documents.

  • Architecture review and trust-boundary analysis
  • CI/CD, signing, artefact integrity, and supply-chain attack paths
  • Model creation, workshop facilitation, and process design
03

Secure Development Lifecycle

Practical SDL consulting for teams that need security built into delivery without slowing engineering to a crawl.

  • Security requirements, design review, and secure coding guidance
  • SAST, SCA, vulnerability triage, and remediation workflows
  • Disclosure, bug bounty, and vulnerability management processes
04

Bespoke Security Tooling

Custom software for analysis, automation, integration, and specialist workflows where standard tools do not quite fit.

  • Python, C, C++, C#, Java, Kotlin, JavaScript, Win32, and Linux tooling
  • Fuzzing harnesses, protocol tooling, parsers, and workflow automation
  • Internal platforms for repeatable security assessment and reporting

Areas Of Depth

Experience across fintech, telecoms, government intelligence, distributed ledger systems, endpoint platforms, and sensitive engineering environments.

  • Offensive security research
  • Reverse engineering
  • Exploit development
  • Windows internals
  • Kernel security
  • Cryptography, PKI & HSMs
  • Intel SGX & confidential computing
  • ARM TrustZone
  • Cloud and Kubernetes security
  • Network protocol analysis

How Engagements Usually Work

  1. Scope the problem. Clarify the asset, threat, constraints, and the decision you need to make.
  2. Investigate deeply. Review architecture and code, test assumptions, build tooling, and validate attack paths.
  3. Leave useful output. Document findings, prioritise fixes, and help teams turn risk into engineering work.

Need specialist security input?

I can help with focused assessments, architecture reviews, threat models, secure engineering strategy, or bespoke tooling for hard technical problems.

Contact information ❯